Appearance
White-Label Easy MCP AI and Hide Its Admin Screens
Hosting companies and agencies often expose the MCP connection to their customers as part of their own service rather than as a third-party plugin. Three constants make that possible: one replaces the plugin's name on every screen a user sees, one hides the plugin's menu and admin pages, and one removes it from the Plugins list. All three are set in wp-config.php or as environment variables, so they belong to the site configuration and cannot be switched off from the WordPress admin.
In this article
Before you start
The three constants are defined in wp-config.php, above the line that reads /* That's all, stop editing! Happy publishing. */, or as environment variables of the same name. They follow the same rules as every other Easy MCP AI constant, described in Configuring Easy MCP AI with wp-config.php Constants: the constant wins over anything saved in the admin, an invalid value falls back to the default and is named in an administrator notice, and on multisite the value applies to every site in the network.
None of them changes how the plugin works. The MCP endpoint, API keys, OAuth sign-in, the audit log, scheduled cleanups and diagnostics all keep running exactly as before.
Rename the plugin
php
define( 'EASY_MCP_AI_BRAND_NAME', 'Acme AI Connector' );The value must be plain text without HTML, and cannot be empty.
Where the new name appears
- The Easy MCP AI admin menu and every screen under it, including page titles, descriptions and notices.
- The OAuth consent screen an AI client sends the user to, and the device-login page for clients without a browser.
- The API keys section on the user's profile page when self-service keys are enabled.
- Administrator notices the plugin adds to the WordPress admin.
- Error messages returned to AI clients over MCP, such as a message telling the client where a missing credential is configured.
The plugin's own About Us page cannot be rebranded, because it is a shared component that names the plugin and its publisher throughout. It is removed from the menu whenever EASY_MCP_AI_BRAND_NAME is defined, even if the value is invalid.
Where the original name stays
- The plugin's entry on the Plugins screen, which comes from the plugin header. Use
EASY_MCP_AI_HIDE_PLUGIN_ROWto remove the entry instead. - The plugin's listing on WordPress.org and its readme.
- Tool names such as
wp_create_post, the MCP server name and other protocol identifiers that AI clients rely on. - The descriptions of the External Data tools sent to AI clients, which tell the client that a credential is configured under Easy MCP AI → External Data. The AI client sees these, the site's users do not.
- Content already stored in the database, such as earlier audit-log rows.
Hide the admin screens
php
define( 'EASY_MCP_AI_HIDE_ADMIN', 'menu' );| Value | Effect |
|---|---|
not defined, or false | Normal administration. |
'menu' | The Easy MCP AI menu, its submenus, the action links on the Plugins screen and the plugin's administrator notices are removed. Every admin page still opens by direct URL, for example wp-admin/admin.php?page=easy-mcp-ai-settings, for users with the manage_options capability. |
true | As 'menu', and the plugin's admin pages answer with a 403 error reading This administration page is disabled by the site configuration. Settings are then managed through constants and WP-CLI only. |
Choose 'menu' when your own staff still need the screens occasionally and know the URLs. Choose true when nobody should reach them from the browser at all.
What keeps working under both modes
- The MCP endpoint and every tool.
- OAuth sign-in and the consent screen, which are rendered outside the admin menu.
- The device-login page for browserless clients.
- Scheduled cleanups and the diagnostics, which still run and still write their report. Only the admin notices that point to the report are suppressed.
- The API keys section on the user's profile page, when self-service keys are enabled. The profile page is WordPress's own and is never blocked.
- WP-CLI, including
wp easy-mcp-ai config export.
Hiding the screens does not lock the settings
EASY_MCP_AI_HIDE_ADMIN only controls what appears in the WordPress admin. A setting that is not defined as a constant keeps its saved value, and under 'menu' an administrator who knows the URL can still change it. Define the settings you care about as constants as well, so they are locked wherever the screen is reached from.
Hide the plugin from the Plugins list
php
define( 'EASY_MCP_AI_HIDE_PLUGIN_ROW', true );The plugin no longer appears on the Plugins screen. WP-CLI still lists it, so wp plugin list, wp plugin update and wp plugin deactivate keep working.
Updates and deactivation move to the command line
A plugin that is not on the Plugins screen cannot be updated or deactivated from there. Use this constant only on sites whose plugins are managed with WP-CLI or a deployment pipeline, and make sure that pipeline applies plugin updates.
A typical managed-hosting setup
A host that provisions sites from a template, exposes the connection under its own name and manages the plugin from its pipeline would ship something like this in every site's wp-config.php:
php
define( 'EASY_MCP_AI_BRAND_NAME', 'Acme AI Connector' );
define( 'EASY_MCP_AI_HIDE_ADMIN', true );
define( 'EASY_MCP_AI_HIDE_PLUGIN_ROW', true );
define( 'EASY_MCP_AI_RATE_LIMIT_PER_MINUTE', 30 );
define( 'EASY_MCP_AI_OAUTH_MIN_CAPABILITY', 'manage_options' );
define( 'EASY_MCP_AI_SELF_SERVICE_KEYS', true );With this configuration a customer never sees the plugin in the admin. They connect their AI client through the OAuth consent screen, which carries the host's name, or create a key from their own profile page, also under the host's name. The host changes policy by editing the template, and every site follows on the next request.
Check that it worked
- Log in as an administrator. With
'menu'ortrue, the Easy MCP AI menu is gone. Withtrue, openingwp-admin/admin.php?page=easy-mcp-aishows the 403 message. - Start a connection from an AI client that uses OAuth, or open
wp-admin/profile.phpwith self-service keys enabled. The consent screen or the profile section shows the brand name. - With
EASY_MCP_AI_HIDE_PLUGIN_ROW, open Plugins and confirm the entry is absent, then runwp plugin listand confirm it is still active. - If an administrator notice reports an invalid deployment setting, the value is not in an accepted form. Check the table above and the value formats in the constants guide.